Trusterio

The product

Your evidence, collected while you sleep

Fourteen read-only connections, a control library that tests itself against them every day, and a short list of the things that genuinely need a person. Here is all of it.

Step one

Connect it, then forget about it

Read-only credentials to the systems you already pay for. Trusterio reads them on a schedule and never writes to any of them — which is also why it will not pretend to have revoked anything.

AWS
accounts, buckets, keys, security groups
Azure
subscriptions, storage, network rules
Entra ID
accounts, MFA, admin roles, joiners and leavers
Google Workspace
accounts, two-step, sharing settings
GitHub
repositories, branch protection, reviewers
Okta
applications, factors, sessions
Intune
devices, encryption, patch level
Jamf
Macs, FileVault, OS version
Kandji
Macs, blueprints, enforcement
Jira
change tickets, approvals, releases
Slack
channels, retention, guest access
Personio
employees, start and end dates
HiBob
employees, start and end dates
BambooHR
employees, start and end dates

Each connection reports when it was last read and what it found. A connection that has gone quiet says so on the dashboard, rather than silently reporting yesterday.

Step two

Controls that test themselves

Every control has a test, and every test has a schedule. The result is a status you did not type in — and a history showing how long it has been true.

Untested is not passing

A control whose test has not run recently is reported as unknown, and unknown lowers your score. Rounding up is how a dashboard becomes a decoration.

One control, many frameworks

Requirements from ISO 27001, SOC 2, NIS2 and DORA point at the same control. Collect the evidence once; it counts wherever it applies.

An exclusion is on the record

Decide a requirement does not apply and the score moves — with your reason attached to it, visible beside the number it changed.

Step three

A short list, with names on it

Findings come out of readings, not out of a workshop. Each one gets an owner and a date, and closing it means the next reading agrees — not that somebody ticked a box.

  • Owners, not a queueA finding with nobody on it is a finding nobody will do. Every one carries a person and a date.
  • Closed by observationMarking a finding fixed does not close it. The next reading of the system does.
  • Risk that argues backA risk you reduced on paper is reported at its inherent score until the control behind it is actually passing.

The rest of it

The three spreadsheets you can throw away

The parts of compliance that usually live somewhere else entirely, in the same place as the evidence that backs them.

The GDPR Article 30 record

Every processing activity with its purpose, legal basis, categories, recipients and retention — and checked against what your Trust Center says you hold. The two cannot quietly disagree.

Joiners and leavers

Read from your HR system rather than typed in. A leaver stays open until a later reading of every directory reports the account gone.

Security questionnaires

Answers drafted from what you have already published, with the sources attached, and checked against them before anybody sees a draft. Nothing is invented.

Next: the page your customers read

Fourteen days. The whole thing.

No card, no sales call, no demo you have to sit through. Your data stays in the EU.

Start free
Product — how Trusterio collects your compliance evidence